{"id":"CVE-2026-100308","published":"2026-09-29T16:17:04.900","lastModified":"2026-09-29T18:56:13.190","description":"Deserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 might allow context-dependent attackers to execute arbitrary operating system commands with the privileges of the loading process via a crafted serialized model directory.\n\n\n\nTo remediate this issue, users should upgrade to version 0.17.0 or later.","cvssScore":7.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwes":["CWE-470","CWE-502"],"vendors":[],"products":[],"references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-119-aws/","tags":[]},{"url":"https://github.com/awslabs/gluonts/releases/tag/v0.17.0","tags":[]},{"url":"https://github.com/awslabs/gluonts/security/advisories/GHSA-64q6-5qv7-cwj9","tags":[]}],"exploitRefs":[{"url":"https://github.com/awslabs/gluonts/releases/tag/v0.17.0","tags":[]},{"url":"https://github.com/awslabs/gluonts/security/advisories/GHSA-64q6-5qv7-cwj9","tags":[]}],"hasPoc":true,"ai":null}